igneum/docs/fud-fixes.md
igneum-labs 7eed16a29a Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).

The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.

Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:39:50 +00:00

64 KiB

Igneum FUD fixes

Internal working list. Written 3 October 2026 against docs/fud-ledger.md version 0.1, docs/spec/06-open-items.md, docs/bench-log.md, and the public text in site/index.html (HP), site/litepaper.html (LP) and site/journey.json (J) as checked this evening. The ledger itself is not changed by this file. Entries are referenced by ledger id; overclaims by item number.

Decisions of 3 October 2026 applied throughout: (a) no development fund, priority fee 80% to miners and provers and 20% to the called app, external jobs 90% to provers and 10% burned; (b) the ledger is internal (superseded 5 October 2026: the ledger is published with the repository at the public testnet); (c) the project is established offshore and the founder's location is never mentioned; (d) deSEC nameservers now, a non-US registrar in December 2026; (e) the dedicated identities exist (GitHub organisation igneum-network with one anonymous owner, Vercel team igneum, Google Workspace on igneum.network).

1. Summary

  1. The ledger holds 80 entries and 78 overclaim items. Every entry appears once below: 64 open or conceded entries across 74 rows in section 2, and 16 answered entries that still carry a fix in section 2.1.
  2. Open: 11 entries after the evening closures of 3 October 2026 (F2, F3, P5, P8, C9, E7, G7, X6 closed by rule or decided; section 4). 7 close on a measurement, 4 on counsel or a search (L1, L2, L4, L5).
  3. Conceded: 45 entries. 13 are already stated in public text, 32 are not.
  4. Answered: 16 entries. All 16 still carry a wording fix, an experiment or a counsel check.
  5. Overclaims: 78 items. 10 already fixed (5, 6, 9, 22, 23, 27, 38, 40, 47, 71), 3 partly fixed (11, 31, 75), 65 still present or still missing. Item 23 is fixed but stale. Item 73 must not be applied as written.
  6. The 3 October decisions close E4 outright, narrow G4, G8 and L3, and change E3, E5, G3 and G5 (section 4). The dev fund removal forces a rewrite of 11 places in the site, spec and design files (row 7).
  7. EXPOSES: six items. CLAUDE.md (full name, other companies, registrar, database region, personal GitHub handle), the cryptographer agent file, the commit handle igneum-labs, the local-time offset on every commit, the earlier ledger text "The founder is in the UK" still in git history, and the ledger itself in the tree. All are fixed in section 5.
  8. Measured since the ledger was written: the 256 MB cache dataset is built and bit-exact on Apple, NVIDIA (CUDA and OpenCL) and an AMD integrated chip; the shortcut is 4.8x slower than honest on Apple; CPU verify is 0.41 to 1.2 ms per warp with the cache; the VDF grinding simulation ran. Items 16, 20, 21, 23, 56 and 78 need these facts, not the ledger's replacements.
  9. By timing: 44 rows now (site text, decisions, accounts; two of them continue into December and mainnet), 12 before the repository goes public (citations, counsel, gate 1 measurements, the phase 2 benchmark), 16 before public testnet (gate 2 and 3 work, policies), 1 before mainnet, 1 with nothing further (F6).
  10. Five most urgent: section 5 steps 1 to 4 (the tree and history must be clean before any public push); rows 1 to 5 (dead links, the miner button, no contact route, listings, Day one); row 7 (dev fund text everywhere); row 9 (the founder is pseudonymous now, the text and the ledger disagree); rows 43 to 46 (trademark and counsel).

2. Every open or conceded entry

Who: the founder (decision or account), Claude (text, spec, code, simulation), counsel, measurement (an experiment that produces a number). When: now, before public repo (opens at the public testnet, August 2027), before testnet (August 2027), before mainnet (November 2027).

# Ledger Issue Fix Who When EXPOSES
1 X1 HP footer, HP nav and the /bench page link to a private GitHub repository Remove the GitHub links (site/index.html line 422, the nav in site/build.mjs) until the repository is public; put them back on the day Claude now no
2 X2 "Get the miner" three times and "Start mining" on HP with no miner Item 60: "Benchmark: January 2027", linking to #journey Claude now no
3 X7 No contact route on HP or LP the founder creates a mailbox on the igneum.network Workspace; Claude adds it to the HP footer and the LP cover (item 77). No public ledger route is needed now the ledger is internal the founder, then Claude now no
4 X8 "exchange listings after" in the LP roadmap (line 422) and J phase 6 Item 58 in both files Claude now no
5 X10 Eleven log entries, all dated 3 October 2026 Add a "Day one" label above the log in site/index.html Claude now no
6 L2 (with E2) Inducement wording: "so the people who show up early get the most" (LP 183), chart caption "Half of the 4 billion cap is mined in the first two years" (LP 184), HP "Half of all IGN is mined in the first two years" Items 54 and 76: schedule facts, no "so" clause. Counsel opinion is row 46 Claude now no
7 E4, E5, G5, G8, O-5.4 Dev fund text everywhere after decision (a): LP Economics (65/15/15/5 paragraph, "Development, paid by outsiders" section), LP Governance (fund bullet, second-client bullet), LP firsts row ("a development fund paid by outsiders"), HP Economics ("Development is paid from fees..."), spec 05 sections 5.2, 5.4, 5.5 and the self-dealing arithmetic, spec README row 5, spec 00 row 5, spec 06 items O-5.4 and O-5.7, docs/design/execution-layer.md lines 143, 210 and 217, the design document (CLAUDE.md already carries the new split) Rewrite to: base fee burned in full; priority fee 80% miner and provers, 20% called app; external jobs 90% prover, 10% burn; no fund. The founder confirms the 15% priority-fee burn is gone on purpose (section 4) Claude, the founder confirms now no
8 E5 HP "Not one coin to a founder, a fund or a stake" while the official client carries a 1% dev fee to the founder's company; LP spreads the dev fee, the pool and the proving business over three sections Item 62 on HP. One LP heading that holds the 1% dev fee, the pool, the proving business, and that these now fund development since there is no fund Claude now EXPOSES: "the founder's company" must be the offshore entity once it exists, never a company the founder already owns
9 G3 The ledger's answer says "The founder's name is on every commit". Decisions (c) and (e) make the founder pseudonymous Do not apply item 73 as written. LP "Who are you?" gets: "The founder is pseudonymous until the team page at public testnet. No cryptographer is hired yet." Decided 5 October 2026: no team page for now; the litepaper says the team is pseudonymous and names no team page the founder decides, Claude writes now EXPOSES: the ledger answer and CLAUDE.md name the founder; see section 5
10 F5 "whole network's hashrate" misread Item 32 Claude now no
11 F10, F4, G8 Pool concentration unstated; LP heading "Speed and finality, powered by miners alone" Items 33 and 43. Heading becomes "Speed and finality, a miner-weighted overlay on proof of work". Name pool concentration as the governance risk Claude now no
12 C3, M3, C8, C11 Kaspa misstated; firsts table; LP 68 "taken over by chips, as Kaspa was" still reads as capture; Conflux missing from the problem section Apply items 4, 7, 8, 10, 11 and 29. Items 5, 6, 9 and 47 are done Claude now no
13 C5 Inclusion compared to finality Item 30 without the "see the FUD ledger" cross-reference Claude now no
14 C2, M1 Chip claims: "no chip can ever", "nothing for a chip to be built for", "same margin that has protected Monero for seven years", "runs for ever ... with no chip built" Items 1, 2, 13, 17, 18, 19, 50, 59, 63, 67, plus the HP Mine card line "nothing for a chip to be built for" Claude now no
15 M10 "bound by memory bandwidth" Item 14 with the 5090 numbers (95 GB/s useful against 1,638 GB/s sequential) Claude now no
16 M5 "memory footprint and instruction count are fixed" while loads vary 40 to 232 Item 15 Claude now no
17 M2, M9 Items 16, 21, 23 and the first item of 78 were written before the cache landed. Bench log 3 Oct: memory-hard dataset built, bit-exact on Apple, NVIDIA and AMD integrated; shortcut 4.8x slower on Apple (closed form was 111x faster); CPU verify 0.41 to 1.2 ms per warp with the cache on one M5 Max core Rewrite items 16, 21, 23 and 78 with the new facts: shortcut closed on Apple, NVIDIA and AMD ratios pending; 10 ms gate met on one core, a 2019-class core pending Claude now no
18 M8 "Any card, any vendor. Bit-exact on Apple and NVIDIA" (LP 126, HP 64); "NVIDIA and AMD both work" (LP 224) Items 20, 56 and 66 updated: bit-exact on Apple Metal, NVIDIA CUDA and OpenCL, Apple OpenCL and an AMD integrated chip; discrete AMD and Intel not yet run Claude now no
19 M13 "Macs mine too" without the ratio Add "at about a fifth of a flagship card; the app shows projected earnings before it starts" Claude now no
20 P2 Launch gas budget unstated Publish the launch budget as a formula: cards proving times shards per card per minute Claude now no
21 P3 "a phone can check it in milliseconds" Item 25 Claude now no
22 P4 "Trustless light clients ... need no multisig" (LP 171) Item 38 (item 9 is done) Claude now no
23 P5 "runs on Igneum unchanged" (abstract and LP 168); "Three things run on Igneum that run nowhere else" Items 35 and 36, plus the abstract sentence; the documented differences now exist in spec 7.1 (P5 closed 3 October 2026), so the replacement can point at them Claude now no
24 P6, C10 "cheapest supplier", "lowest cost", "last provers to switch off" (LP 73, 222, 277, 293) Items 12, 49 and 55, plus the "guaranteed income floor" paragraph Claude now no
25 P7 "a block with a wrong state cannot exist"; "Nothing in it ever needs a human" Items 3 and 26 Claude now no
26 P10, E7 Economics says outsiders pay in IGN and part is burned; the miner section says they pay in their own money; "Stablecoins at genesis ... through the proof bridge" (LP 176, 284) Items 40 and 71 applied 3 October 2026 (E7 decided, spec 7.3); item 52 (the P10 contradiction in Economics) still open Claude now no
27 E1, E6 Supply states the cap, not the tail-emission trade-off; halvings presented as fact, not a bet Two sentences in Supply: the tail alternative and why the cap was chosen; the halving schedule is a bet, a tail can be added by 90% signalling Claude now no
28 G1 "named reviewers" who do not exist; "The specification is public" (LP 271) Items 48 and the third item of 78 Claude now no
29 G2 Method undisclosed Item 72. Keep the Co-Authored-By trailers in the history: they are the evidence the entry cites Claude; the founder confirms the trailers stay now no
30 G4 "There are no admin keys" (LP 236), "0 admin keys" (HP) Item 45 minus the fund contract; HP tile becomes "0 admin keys in consensus" Claude now no
31 G5 "second independent node client, funded from the development fund" (LP 237) Item 46 rewritten: "At launch there is one node client. A second independent client is not in the 13-month plan." The funder is row 47 Claude now no
32 G6 "Pools cannot censor" (LP 235) Item 44 Claude now no
33 C1, C12 "Monero's idea, finished for GPUs" (LP 119, HP 57) Item 68 in both Claude now no
34 C6, X4 Roadmap does not say the combination is the risk; "Dates slip. Gates do not." missing Item 69 plus one sentence: each piece has a precedent, the combination has none, and that is what the gates price Claude now no
35 C7 New miners vote after a month, unstated One sentence in Finality: a new miner's vote reaches full weight after a month; its rewards do not wait Claude now no
36 F1, X9 First month: Finality has the thin-weights sentence (item 31 partly done); "Fair launch" and "What Igneum does not claim" do not; "exchanges are told to treat it so" missing; "no amount of fresh hashrate" remains Finish item 31; apply item 75 and the second item of 78 Claude now no
37 F8 Day counts quoted as facts Item 74 Claude now no
38 F2 The two-hour window's exposure unstated Item 34; the source text is now spec 3.3.2 (F2 closed by the floor, 3 October 2026) Claude now no
39 X3 "All of it will be on this page, live" with no date Item 61 Claude now no
40 F12 "Nothing in Igneum's consensus depends on anything outside Igneum" (LP 166) Scope to "no other chain's state"; name the code dependencies (SP1, BLS12-381, class-group VDF, rusty-kaspa) in one line Claude now no
41 F13 Why prove if every node executes: unstated One sentence under the 20% row: the share pays a standing prover population, and the proof serves light clients, bridges and sync from a proven checkpoint Claude now no
42 F6 Equivocation costs history, not coins Stated (LP 164, design doc). Nothing further none no
43 L5 No trademark search recorded Search EUIPO, USPTO and UK IPO in classes 9, 36 and 42; record the result outside the repo; the name stays provisional until then the founder, counsel if a hit now EXPOSES: any application comes from the offshore entity, never from the founder or a company he already owns
44 L3 US registrar, US nameservers, US host Now: deSEC nameservers (in progress); recreate the Vercel records at deSEC and re-verify every domain in the Vercel project. December 2026: non-US registrar when the transfer lock ends. Before mainnet: IPFS mirror, ENS or equivalent name, site content hash in the repo and in genesis, seed nodes as addresses in the client the founder (accounts), Claude (mirror, hashes) now, December, before mainnet EXPOSES: the ledger and CLAUDE.md name the registrar and the host; keep both out of the public tree
45 E8 Founders seed the DEX Stated. Whether to do it at all goes to counsel in row 46 counsel before public repo no
46 L1, L2 Howey and promotions: founder business, founder-seeded DEX, launch grants, listings (row 4 removes listings) Counsel in the entity's jurisdiction reviews the founder-business paragraph and the promotions question before litepaper v0.2. The ledger's "offshore, parked" becomes "offshore, being established". The founder decides whether igneum.co.uk stays in the redirect set (a weak UK hint; WHOIS is redacted) counsel, the founder briefs before public repo EXPOSES: the brief names the entity's jurisdiction, never the founder's residence
47 G5 The second client has no funder now the fund is gone Decide: the operating company, a grant from the proving business, or not in the plan the founder now (decision), before mainnet (client) no
48 M4 Firsts row is done (item 5); ProgPoW and Ravencoin are cited nowhere Clone the ProgPoW specification and the Ravencoin repository into vendor/; cite path and commit in the spec Claude before public repo no
49 C8, C3 Ergo, Ravencoin, Conflux and rusty-kaspa claims are from memory Cite each from its repository; label approximate until then Claude before public repo no
50 M1 ASIC gain under 2x is a target Public benchmark, leaderboard by card model and a standing bounty with the January 2027 release (O-1.17). Bounty terms and funding are the founder's the founder (terms), Claude (benchmark), measurement before public repo EXPOSES: the bounty payer and terms carry the entity, not the founder
51 M5 Load count varies 6x O-1.2: exact 16 load positions in the generator, re-fuzz 10,000 programs, confirm the loads-per-hash column is constant measurement before public repo no
52 M6 Weak programs unmeasured O-1.3: census of at least 10^5 programs and a rejection rule in the generator measurement before public repo no
53 M7 Ad hoc seed derivation, no analysis O-1.1: standard hash into the seed words, new vectors. O-1.4: external review scoped to the fair-lottery properties Claude (code), then review before public repo no
54 M8 Discrete AMD and Intel never run; the fuzz set has run on Metal and the CPU only O-1.15: the proto-opencl commands on a discrete AMD card; the 10,200-program fuzz and the 14 edge programs on NVIDIA and AMD; Intel Arc after measurement before public repo no
55 M2 Shortcut ratio measured on Apple only O-1.5: inline kernel on the 5090 and a discrete AMD card. O-1.6: the time-memory curve and the hoisting attacker measurement before public repo no
56 M9 Verify gate measured on one M5 Max core O-1.14: the Rust verifier on a 2019-class laptop core at 104 and 144 loads measurement before public repo no
57 P1, P3 No SP1 shard proven on any card; wrapper cost unknown Phase 2 benchmark: shard time on a 3060-class card and the wrapper cost on consumer hardware, published with the January 2027 release measurement before public repo no
58 L4 Paying testnet miners needs an entity, terms and tax treatment Entity first (decision c); counsel writes the terms before phase 5 counsel before testnet no
59 L6 Dollar-paid job market read as money transmission Counsel confirms the no-custody structure before phase 4 counsel before testnet no
60 M11 Hourly compile on real rigs unmeasured O-1.16: miner client prototype on a multi-card rig; compile time and failure rate per hour measurement before testnet no
61 F1 No weight in the first month O-3.1: launch-month simulation; decide the no-certificate-for-30-days rule; the litepaper states it either way Claude (sim), the founder (decision) before testnet no
62 F3 Participation grinding through the bitmap Closed by rule 3 October 2026: spec 3.3 Q2 and 3.4.1, participation from every vote seen in blocks. Remaining: O-3.3, the per-block vote bound and the re-run under the block reading Claude (sim) before testnet no
63 F7 Checkpoint depth 60 is a placeholder O-3.2: devnet with regional latency, reorg-depth distribution per block rate measurement before testnet no
64 F2 Presence window as an eclipse vector Closed by rule 3 October 2026: spec 3.3.2, the 56.7% floor. Remaining: O-3.7, the devnet single-node eclipse as confirmation; no rule choice measurement before testnet no
65 C4 The overlay changes GHOSTDAG's guarantees O-3.8: devnet runs with the module on and off; adversary simulation from real pool-hashrate traces measurement before testnet no
66 P8, C9 First-come shards centralise Closed by rule 3 October 2026: spec 7.2, sortition to 8 provers for 10 s then open, no shard bond. Remaining: O-5.1, the parameters on the phase 4 devnet measurement before testnet no
67 P5 EVM semantics on a DAG Closed by spec 3 October 2026: spec 7.1 (number, timestamp and its monotonicity rule, blockhash, PREVRANDAO from the epoch VDF, coinbase, gas limit, chain id, quoted gas price); O-2.8 removed done done no
68 P7 Soundness-bug handling Spec rule: a full node rejects a proof whose state root differs from its own execution; the proof-system version has a stated human emergency path Claude before testnet no
69 P9 Shard bond and timeout open O-5.6 on the phase 4 devnet measurement before testnet no
70 E7, P10 Genesis bridge trust model undecided Decided 3 October 2026: spec 7.3, no bridged stablecoins at genesis, no official bridge, proof bridge with the consensus proof in phase two; LP and HP text changed. Remaining: O-5.2, how the IGN settlement switch is activated done (the founder); Claude for O-5.2 before testnet no
71 G1 No cryptographer; no named reviewers Contract a cryptographer for phases 1 and 2; name and pay external reviewers before gate 3 the founder before testnet EXPOSES: contracts come from the entity; reviewers are told the founder is pseudonymous
72 G7, X6 The update channel is a key; the installer is a honeypot vector Decided 3 October 2026: spec 08-client-security.md (reproducible builds, release key in genesis and in hardware, no silent updates, consensus only by 90% signalling, notarised builds, official sources with the hash, seed confirmed before mining, hardware wallet, the permanent line). The line is on HP and LP. Remaining: O-8.1, the key custody policy and toolchain publication the founder (key custody) before testnet no
73 X5 "1,000 independent miners" is a Sybil number Define independence measurably (distinct ASNs, benchmark hardware fingerprints, pool attestations) before the gate is tested Claude drafts, the founder decides before testnet no
74 G4 Genesis contract and bridge key policies Publish each genesis contract's key policy before launch (O-5.4 without the fund contract) Claude, the founder before mainnet no

2.1 Answered entries that still carry something

Ledger What remains Row
M3 Items 11 and 49 wording 12
M8 AMD discrete and Intel; fuzz set on NVIDIA and AMD 18, 54
M10 Item 14 wording 15
M12 The lottery half is conceded; covered by the first-month rule 36, 61
F4 Call it an overlay on proof of work 11
F9 The gate 3 experiments decide the denominator rule 64
F11 The grinding simulation ran (proto-vdf: +3.62 blocks per epoch at 30% without the delay, 0 with it). Left: O-4.9 re-run with the census distribution; O-4.1 second cryptographer reads classgroup.rs against chiavdf 52, 71
F12 Scope the "nothing outside" sentence 40
F13 Say what the 20% buys 41
P9 Bond and timeout 69
E2 Inducement wording and counsel 6, 46
E3 The arithmetic changes with the new split; see section 4 7
E4 Closed by decision (a) 7
C1, C12 Item 68 33
L6 Counsel before phase 4 59

2.2 Round 3 entries (3 October 2026, evening)

Added after docs/review/round-3-2026-10-03.md. Rows continue the numbering of section 2. "code, owner consensus engineer" marks a row that needs node code and is not Claude's text work; the ledger status for those stays as the review left it.

# Ledger Issue Fix Who When EXPOSES
75 F18 LP Finality: "a silent minority cannot freeze finality and a lock never waits for miners who have left" Fixed 3 October 2026: the exchange engineer's replacement sentence in LP Finality; "Finality that never pauses" item added to "What Igneum does not claim" Claude done no
76 P13 LP Proving: "Miners claim shards with a small bond" Fixed 3 October 2026: "Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond" Claude done no
77 E11 HP tile "IGN burned from jobs, at launch"; the quoted paragraph had already left the trimmed page Fixed 3 October 2026: tile reads "phase two"; caption adds "Jobs are paid on the customer's chain at launch; settlement in IGN with a 10% burn follows the proof bridge in phase two" Claude done no
78 L7 LP Economics heading "Where the price comes from" and the burn-reduces-supply sentence Fixed 3 October 2026: heading "Where fees go", sentence deleted. Counsel reads the section under row 46 Claude; counsel done; before public repo no
79 P11 Native-execution veto written against the node's current selected chain Spec 7.2 item 5 rewritten 3 October 2026, relative to the carrying block's own selected-parent chain. docs/design/execution-layer.md 5.5 and D12 rewritten and the two-node reorg test added to its 8.5 the same evening Claude done no
80 F17, P8 Shard sortition per key; keys are free; launcher mints 8 per card Spec 7.2 step 2 draws by weight and spec 3.1 W6 states the principle, 3 October 2026. Left: client default of one vote key per operator (MINERS multiplies workers, not keys); S2 and the bitmap size (O-3.5, O-3.12) before the voter count can cross 8,192 Claude (spec, done); miner client (default) before testnet no
81 M14, F14 Weight and presence windows in DAA seconds under a lagging retarget; no finality run with a DAA model Spec 3.1 W2 and 3.3 Q1 in past-median time, weight per 60-s bucket, 3 October 2026 (simulated form kept beside it). O-3.14 added: finality_v2.py with the DAA in the loop, 50x pulsed renter, both W2 forms, logged in the bench-log. Controller choice is gate 2 (O-2.1) Claude (spec, done); measurement (O-3.14) before testnet no
82 F15 Merge depth called the reorg bound; the code's bound is the finality depth, 43,200 DAA s Spec 2.1, 3.8 and 3.9 name the finality depth, in median time (12 h), 3 October 2026; simnet reorg test (2, 6, 13 h forks) written into 2.1 for gate 2. LP Finality (first-month and merge-depth sentences) and "What Igneum does not claim" item 4 rewritten the same evening: 12-hour finality depth, merge depth a merge limit. Left: the simnet test Claude (done); measurement (simnet) before testnet no
83 E9 Spec year 365 days; code 365.25 (31,557,600 s, halving 63,115,200 s, 3,168,808,781 sompi/s) Spec 2.5 follows the code, 3 October 2026. Divergence record for the code owner: the spec was changed, the code was not; add a test that reads the published numbers (year, halving interval, per-second rate, ramp) and asserts them against consensus/core/src/igneum.rs, and decide O-2.6 (8 decimals fits the u64 cap, 18 does not) before the first testnet genesis code, owner consensus engineer before testnet no
84 E10 Spec said reds unpaid and "more blocks never means more coins"; code pays reds in the DAA window to the merger and mints per block Spec 2.5 follows the code, 3 October 2026. Divergence record for the code owner: no code change; the litepaper Speed sentence ("never per block") was rewritten the same evening to match 2.5: emission per block on a schedule keyed to difficulty-adjusted time, reds in the window paid, coins track blocks within the controller's accuracy Claude done no
85 G9 Release key: single steward, lost key unrevocable Spec 8.2 items 2 and 5 rewritten 3 October 2026: key chain, rotation signed by the current key, revocation signed by the previous key (pre-signed certificate for K0), published in a block; policy before the client ships, with entity and jurisdiction. Left: the policy itself and the second holder (O-8.1, L1) the founder (custody), counsel before testnet EXPOSES: the policy names the entity, never a person's residence
86 M15 Pre-validation PoW cost: any past timestamp or claimed DAA score forces a 256 MiB cache fill before the checks that would reject the header Run check_difficulty_and_daa_score and the past-median check before check_pow_and_calc_block_level in validate_header; derive the day from DAA score or the selected parent's window; KEEP 4; per-peer cap on cache builds. Review's first of five code, owner consensus engineer now no
87 M20 Pruning proofs validated with the kHeavyHash stub: a fresh node cannot sync from a lottery-mined pruning point; a loosened check is forgeable with an existing ASIC Thread the epoch and day seeds through pruning_proof/validate.rs, apply.rs and mod.rs (fork map a4, O-2.5); test by syncing a fresh node from the 30-hour devnet code, owner consensus engineer before testnet no
88 P12 An aggregator rewrites ProofRecord.provers and takes the pool; shard proofs do not commit to the prover Shard statement gains the prover's payout key as a public input, aggregation carries the keys as public outputs, a record whose list does not match is invalid; acceptance test A5 checks the match. Spec 7 and docs/design/execution-layer.md 5.1, 5.6 and 9.2 change with the code code, owner consensus engineer (with execution engineer) before testnet no

Not yet rowed from round 3: M16, M17, M18, M19, M21, F16, P14, P15, C13, L8, G10, X12. Their fixes are in the ledger entries.

2.3 External review entries (3 October 2026, night)

Added after docs/review/external-2026-10-03.md. Rows continue the numbering of section 2.2.

# Ledger Issue Fix Who When EXPOSES
89 P16 Phase 2 gate passable by shrinking the shard (design R2's fallback); no end-to-end standard J phase 2 gate rewritten 3 October 2026 (night): fixed workload, job received to accepted proof, no growing backlog, three independent reproductions. Left: O-7.1, the benchmark itself; R2's fallback sentence to say a halved shard is a new declared workload, never a pass Claude (J, done); measurement before public repo no
90 F19 Bought, borrowed or stolen vote keys carry 30 days of weight; only renters are modelled O-3.15: finality_v2.py key-transfer scenario against the same share as fresh hashrate, with the 40/40/20 row; decide W5 re-earning and weight decay Claude (sim), cryptographer before testnet no
91 F20 No statement of what holds during a finality pause; the seed pipeline from uncertified checkpoints is a proposal (O-4.3) O-3.16: decide O-4.3, write the four pause guarantees into spec 3.7, devnet stall through 3 epoch boundaries Claude (spec), measurement before testnet no
92 P17 Three states shown; included is a list Design 2.4 written 3 October 2026 (night). Left: state field in igneum_getTransactionStatus, the phone-app and explorer words, the O-7.2 conformance set Claude (design, done); code, owner execution engineer before testnet no
93 E12 No stress test of mining against proving under shocks; R8 has not run O-5.9: R8 extended with 10x external pay, falling price, operator exit, unfulfilled assignments, profit-only clients; then the phase 4 devnet Claude (sim), measurement before testnet no
94 E13 No payment-route diagram; the routes are spread over LP Economics, the HP tiles and the customer brief O-5.10: one figure, one route per row (emission, base fee, priority fee, jobs at launch, jobs after the bridge, client dev fee), in LP Economics and the brief; operator revenue never summed with protocol revenue Claude now no
95 E14 No funding table Cost lines against sources, labelled funded / dependent on revenue / unfunded, with the late-revenue case; internal until counsel reads it; unfunded lines stated in LP the founder (numbers), Claude (table) before public repo EXPOSES: sources name the entity, never a company the founder already owns
96 E15 Security budget through halvings with low fees, no demand and a flat price: unmodelled O-5.11 model; the failing year and price stated in LP Supply next to the tail alternative (row 27) Claude (model) before mainnet no
97 G11 Repository private; harnesses, vectors, simulators and spec could be public now, labelled experimental the founder decides the components, licence and date; section 5 steps 1 to 7 first in any case; one proof-request workflow and one reference app before any app set the founder now (decision) no
98 X13 Phase 4 gate is a signature; the brief says no payment Brief v0.2: agree workload, proof format, deadline, failure rate and price before the pilot; publish the outcome and the customer's reason; paid pilot added to the J phase 5 line; entity and terms per L4; timing is the founder's Claude (brief), the founder, counsel before testnet no
99 X14 Independence undefined; concentration in hashing, signing, proving and aggregation unreported O-X.1: define independence; four concentrations as top-1, top-3 and top-10 shares over 30 days on the live page beside the gate Claude (observer), the founder (definition) before testnet no
100 X15 "The chain runs without its founders" untested O-X.2: 24-h founder shutdown on the public testnet at a published time; record what continues measurement before mainnet no
101 X16 No evidence page; one voice for implemented, team-tested, reproduced and reviewed O-X.3: one row per public claim with status, version, test, result and one of the four labels; audits tied to versions; ships with the benchmark Claude before public repo no
102 X17 Client shows gross earnings only; no mining and proving split, no failed jobs, no isolation design O-8.2 display rules (client and phone-app 4.1, written 3 October 2026 night); O-8.3 isolation design before the first external job; update control already spec 8.2 item 4 Claude (design); miner client (code) before testnet no
103 M22 Bounty has no metric, judge, eligible hardware or fund; 2x is not the economic line Scoring rules (per-program distribution of hash/s and hash/J, capital per unit of hash rate, longevity, shortcut classes) published with the benchmark; funder, judge and reward are the founder's; public claim limited to "competitive against the best independently proposed design across tested workloads" Claude (rules), the founder (fund) before public repo EXPOSES: the payer is the entity (row 50)

2.6 Sweep (5 October 2026, evening), round 6: the experiment and status items

Appended by the consensus engineer and cryptographer agent (worktree igneum-wt-fud-a); the wording items of the same evening are the other agent's section. Rows below name the earlier row they touch; nothing above is rewritten. Evidence in docs/bench-log.md, "5 October 2026 (evening), FUD ledger sweep round 6".

Row touched Ledger What changed (5 October 2026, evening) Who next When
106 G12, X18 Done and rolled out (0.3.5, 07:33 BST; every node prints the digest, the digest refused the early-restarted hand node for 20 min at 08:15 BST). Left: the digest-less allowance on devnet and simnet, rollout-v2.sh two-field write consensus engineer before testnet
107 F23, F24 Done and rolled out (0.3.5): 0 "names N voters" refusals and 0 CONFLICTING on five machines in 10 h; checkpoints 2970 and 2971 re-determined on three machines at 10:56 BST with no hole none done
108 M26, M27, X21 Done and rolled out (0.3.5): the 0.3.4 prepare storm (4,299 refusals in 2 h on PC 1) ended at the 0.3.5 start, 0 prepare-failed since; cards read mismatched=0 faults=0. Left: the edited-kernel red-card test on a PC miner lead when convenient
117 M20 Done and rolled out (0.3.5, m20-pruning, 4 tests). Left: the live test, a fresh node syncing once the pruning point leaves genesis (still genesis at DAA 113,289 at 16:00 UTC) consensus engineer tonight or tomorrow, when the point moves
2.5 (M30, "the flood memory growth") M30 Done and rolled out (0.3.5): cache builds equal node restarts (5 / 5 / 8 in 10 h), none at the epoch rolls none done
(F25) F25 Done and rolled out (0.3.5 merge 7abce72); both harness libraries ran tonight none done
(F21, F22) F21, F22 Shipped in every node since 0.3.4; the switch finality_v3_activation_daa is absent from the live override file. Rollout = N3 of docs/plans/finality-v3-rollout-devnet.md the founder (N3), then the operator steps now
50 M1 Program space counted (about 2^1550 shapes under a 2^256 seed; the per-program spread is 1.10x under version 2). The claim stays a target; the experiment stays the bounty and benchmark the founder (M22 terms), Claude (benchmark) before public repo
60 M11 Measured on five machines, four compilers, three vendors over 10 to 12 boundaries each: NVRTC 0.6 to 1.1 s, OpenCL 7 to 12 s (iGPU 55 to 124 s beside builds), Metal under 0.5 s plus the race; 5090 race +0.00%, base twice. Left: multi-card rig, ROCm (hardware) measurement (O-1.16) before testnet
55 M16 Cost model written (docs/analysis/m16-recompute-attacker-2026-10-05.md): 1.5x to 2.4x at equal integer budget, 3x to 6x with a fixed-function factor, the mixer-cost lever. Left: the 64 MiB-cache inline kernel on the 5090 (PC job), O-1.6 measurement; the founder at gate 1 before public repo
121 M21 Block sizes measured (p50 723 B, max 6.9 KB); k 5 at the measured p99, 6 with 500 KB bodies, 18 at 5 s. Left: O-2.2 with proof-bearing bodies consensus engineer before testnet
57 P3 The certificate half measured in a phone-sized tab (139 to 155 ms cold, 58 to 68 ms warm, on the laptop's CPU; no phone); the wrapper is unbuilt measurement (phase 2) before public repo
69 P9 Parameter table written from the live numbers (8 assignees, window 10 DAA s today, 25 s proposed, no shard bond, 120-s job claim timeout, S_p 30,000 at v1). Left: O-5.1 and O-5.6 values on the phase 4 devnet the founder (values), measurement before testnet
(P14) P14 Fixed in spec 05 section 5.1: one controller, the EIP-1559 step of next_base_fee. Left: design 4.1's "smoothed" phrase; R1 band, R8 execution engineer when convenient
(F16) F16 Two options priced, B recommended (never withdraw, as 3.11.4). Left: replace the 3.5 paragraph, finality_conflict in the node, the forced double-certificate test the founder (gate 3), consensus engineer before testnet
73 X5 Measurement defined: N_ind = distinct (ASN, machine fingerprint, pool attestation) classes among keys above dust; today N_ind by fingerprint is 5 for 21 keys. Left: the observer's ASN and fingerprint columns, the pool statement format Claude (observer), the founder (definition) before testnet
65 C4 The overlay measured against bare GHOSTDAG on the same binary (tools/finality-attacks/c4.mjs): see the ledger entry and the bench-log table cryptographer before testnet
43, 44, 46, 58 L1 to L5 Untouched; decision owner line added (the founder, with counsel) the founder, counsel as rowed
9 G3 Untouched; decision owner line added (the founder) the founder now

3. Overclaims still in public text today

Checked against the files this evening. "present" means the quoted text is still live. "missing" means the item is an addition that has not been made. "fixed" means the replacement is in. Line numbers are from the stripped page text, not the HTML.

Item Where Status Note
1 LP cover present
2 LP abstract present
3 LP abstract present
4 LP firsts intro present "six of the pieces are firsts"
5 LP firsts row fixed ProgPoW and KAWPOW named in the adds column
6 LP firsts row fixed now "whose state is proven every block" in substance
7 LP firsts row present "immune to hour-long rentals"
8 LP firsts row present "Kaspa's fair launch, with no utility"
9 LP firsts row fixed phase two stated in the adds column
10 LP problem present "the first chain built so that it can never be taken away again"
11 LP problem partly Ergo and Ravencoin named; "taken over by chips, as Kaspa was" still reads as capture; Conflux missing
12 LP problem present "cheapest supplier"
13 LP glance present
14 LP mining present "bound by memory bandwidth"
15 LP mining present
16 LP mining present rewrite with the cache measurement (row 17), not the ledger's wording
17 LP mining present
18 LP mining present
19 LP mining present
20 LP vs RandomX present rewrite with AMD integrated included (row 18)
21 LP vs RandomX present now largely true: measured 0.41 to 1.2 ms with the cache on one core; say "on one core"
22 LP vs RandomX fixed HP too
23 LP measured so far fixed, stale the cache has landed and was measured on the 5090 and AMD; update the paragraph
24 LP proving present "the one useful GPU workload"
25 LP proving present
26 LP proving present
27 LP proving fixed
28 LP proving present "No other proof-of-work chain has a seat in it"
29 LP speed present "proven on Kaspa"
30 LP speed present replacement must not cite the ledger
31 LP finality partly first-month sentence added; "no amount of fresh hashrate" and the two-thirds clause missing
32 LP finality present
33 LP finality missing pool sentence not added
34 LP finality missing two-hour exposure not added
35 LP building present also the abstract "runs on Igneum unchanged"
36 LP building present
37 LP building present
38 LP building fixed applied 3 October 2026
39 LP building present "Canto and Blast proved"
40 LP building fixed applied 3 October 2026 with the decided text, not the ledger's replacement
41 LP builders ask present
42 LP builders ask present
43 LP governance present
44 LP governance present
45 LP governance, HP tile present
46 LP governance present must also lose the fund (row 31)
47 LP miners ask fixed
48 LP miners ask present
49 LP miners ask present
50 LP not claimed present
51 LP not claimed present
52 LP economics present
53 LP economics, governance present superseded: no fund; rewrite the whole section (row 7)
54 LP supply present
55 LP miners present
56 LP miners present rewrite with the AMD integrated result (row 18)
57 HP Mine card present "approximate" missing on HP
58 LP roadmap, J phase 6 present both files
59 HP hero present
60 HP buttons present three "Get the miner" plus "Start mining"
61 HP live panel present
62 HP economics present
63 HP hero, HP Mine card present both places
64 HP hero present
65 HP footer, /bench nav present
66 HP vs RandomX present items 20 and 21 present, item 22 fixed
67 HP vs RandomX present
68 LP and HP heading present both
69 LP roadmap missing
70 LP mining table present
71 LP builders fixed heading, the Arbitrum and Base line, "an Ethereum bridge, ship at genesis" and the builders-ask answer, 3 October 2026
72 LP cover missing the sentence names the method only, never a location
73 LP who are you do not apply the founder is pseudonymous now; use the row 9 text
74 LP finality missing
75 LP fair launch partly Finality has the first-month sentence; the fair-launch paragraph and "exchanges are told" do not
76 LP supply, chart caption, HP present three places
77 HP and LP present no contact route anywhere
78 LP not claimed missing the first of the three items needs the cache result, not "can be shortcut 110x"

2.4 Round 4 entries (4 October 2026, afternoon)

Added after docs/review/round-4-2026-10-04.md. Rows continue the numbering of section 2. Effort is the review's estimate in hours.

# Ledger Issue Fix Who When EXPOSES
104 X23 Either relay secret queues administrator PowerShell on the PCs; the intake key is the relay key, is in 6 tracked files and ships in every package; the relay-clients zip with both secrets is hosted behind the dl token Zip off the host; rotate the relay token; a relay key of its own; a second per-machine secret or a signature for run; rotate the intake key and repackage (2 h) the founder (rotation), relay owner now EXPOSES: the PCs are the founder's own machines
105 G13 The OTA manifest is signed over an installer whose node and worker binaries arrived unsigned from the dl host; signing is automatic from the latest green run Sign payload-inputs.zip on the Mac, verify in CI; OTA_SKIP=1 by default, the signing step names the run (2 h) release engineer now no
106 G12, X18 IGNEUM_POW_* sets the schedule on every network; no params digest or genesis hash in the handshake; a finality mismatch is a WARN; rollout-v2.sh drops the finality block Delete the fallback; digest plus genesis hash in the version message, refused on mismatch; the WARN becomes a refusal (4 h) consensus engineer (code) before testnet no
107 F23, F24 Node-local equivocation ban time; checkpoint determination never revisited Carrier-DAA bans; re-determine on a reorg deeper than d; two-node tests (4 h) consensus engineer, cryptographer (code) before testnet no
108 M26, M27, X21 Frozen fault-guard baseline loops; no prepare rate limit; mismatches never acted on and invisible in the app Baseline updated on a trip; one prepare per pair per epoch; stop at 3 mismatches, shown on the card (3 h) miner-community-lead, app owner (code) now no
109 E16 The 20% pool is an OP_RETURN on the live chain; LP 396 and 414, HP 306 and 446 say it pays provers "Burned until the payout ships; no prover is paid today" in both places; burned-so-far on the live page Claude now no
110 L9 HP "100% to miners and provers", "0% anyone else"; no devnet-value statement beside Get the miner or on the live page The disclaimer beside the button and on /live; the tiles match the LP dev-fee sentence Claude now no
111 M29 LP 424 describes earnings in currency, a hardware wallet and proving the app does not have Rewrite to 0.3.3; earnings, currency and the hardware wallet become a roadmap sentence Claude now no
112 F21 LP 511 says a third of the blocks is needed to split finality in a partition The round-4 section 1 (b) sentence Claude now no
113 X24, X25, X26, X27 Token in the URL path and printed; agent self-installs at every start; permanent feed with the dl token in bodies; free-text from and no clean rotation Header token in every client, HSTS, masked prints; arm only on reboot_continue; retention and a cap; sender binding; documented rotation (3 h) relay owner now no
114 G14 The intake key (8 commits), the dl token (1), the review files, 51 files with the first name, local-time stamps Section 5 step 4's rewrite list extended; TZ=UTC now the founder, Claude before public repo EXPOSES: yes, the whole row
115 X19, X20, M25, M28, X22, X28, X29, E17 The minors of round 4 (node knobs and silences, cold-sync cost, miner day length, kernel commitment, restart paths, relay hygiene, host and file modes, unlogged economics inputs) As each ledger entry says; the stray token-named file and the 0644 modes today consensus engineer, miner-community-lead, relay owner, Claude when convenient no
116 X30 Bench page private strings; /api/live addresses, key hashes, payout addresses; the mobile menu Fixed 4 October 2026: ac89a37, 6b644a6, 2d8f09c, 621f5cc Claude done no

2.5 Ledger sweep (night of 4 to 5 October 2026)

Added by docs/review/ledger-sweep-2026-10-05.md, which holds what ran, what did not and why. Rows continue the numbering. Effort in hours. Items owned by the fud-consensus branch (F23, F24, G12, X18, the flood memory growth) and the testnet-prep branch (the base-fee floor, testnet parameters, G13, G14, public text) are not repeated here.

# Ledger Issue Fix Who When EXPOSES
117 M20 Pruning-proof headers are still checked with the kHeavyHash stub on devnet-v4 (pruning_proof/validate.rs:192, apply.rs:74, 200, mod.rs:207), and validate_trusted_header skips pre_pow_validation (round 4) Derive the epoch and day of a proof header from the proof's own headers (fork map a4, O-2.5), replace the stub call, run the bits and DAA checks on trusted headers; test: a fresh node syncs a fast-time simnet past its pruning depth (6 h) consensus engineer before testnet no
118 X20 Cold sync walks the selected chain once per checkpoint index from index 1 (processes/finality.rs:204) Start from the last certified index carried in headers and walk once; test on a 10^5-block fast-time simnet, time to first resolution (2 h) consensus engineer before testnet no
119 P15 The RPC block's gasLimit is one block's B_e beside a segment's summed gasUsed (proving branch, igneum/exec/src/rpc.rs:355-356) Report k x B_e for a k-block segment, or document the invariant break for Blockscout (R10) (1 h) execution engineer before a public RPC no
120 M28 Nothing commits the seed to the kernel text the worker compiles; no kernel hash exists on any branch A hash of the emitted kernel in program.json, derived from the seed by the miner and checked by both workers; one sentence in the docs that the chain commits to the seed, not the text (3 h) miner lead before testnet no
121 M21 k = 18 is Kaspa's table value; calculate_ghostdag_k gives k 5 at the cloud devnet's measured p99 of 0.67 s and k 55 at a 20-s bound, and proof-bearing bodies are unmeasured Run O-2.2 with bodies of the size design 5.4 implies, take the p99 propagation, re-derive k with the fork's function (the table is in the ledger entry) (3 h) consensus engineer before testnet no
122 X29 The live node's gRPC listens on every interface (igneumd on *:26610, read-only check 5 October); the file modes are fixed --rpclisten=127.0.0.1:26610; PC 2 through a tunnel or its own node (0.5 h) app owner, the founder now no
123 M14, F14 O-3.14 (the finality simulation with the DAA in the loop under both forms of W2) has no DAA model inside finality_v2.py; the chain-model result (no amplification under either controller) stands in for it Add a lagging retarget to finality_v2.py (Kaspa's sampled window and rule v2), run the 50x pulse under both W2 forms, log the day the renter crosses a third (4 h) cryptographer (sim) before testnet no
124 F1, O-3.1 Spec 06 row O-3.1 still said "not yet in sim/" and the ledger's launch-month arithmetic was in prose only Done in the sweep (5 October 2026): rows O-3.1, O-3.14, O-5.9 and O-5.11 of spec 06 carry tonight's evidence (O-3.15 was already marked decided) Claude (spec) done no
125 X14 Only hashing concentration can be computed from what the observer keeps; signing, proving and aggregation need certificate and proof-record extracts The observer stores signer bitmaps per certificate and prover keys per proof record; a nightly top-1/3/10 table on the live page (3 h) app owner (observer) before testnet no
126 E12 The devnet half of O-5.9 (profit-only prover clients, f_p and B_p paths) Phase 4 devnet run as the ledger entry states (4 h) execution engineer before testnet no
127 M25 Confirmed 5 October 2026 (sweep batch 3): a miner started with a different IGNEUM_POW_DAY_MS builds its cache for another day and every block is rejected as BlockInvalid / block has invalid proof-of-work, with no line naming the day (0 of 4 accepted against 7 of 7 for the control) The day length (or the day index) in the template beside pow_epoch, the miner takes it from there and ignores the environment; the node's PoW rejection names the engine's day and the header's day (1.5 h) miner lead, consensus engineer before testnet no

2.7 Close round 1 (5 October 2026, night)

Appended by the public-text closer (worktree igneum-wt-ledger-text, branch ledger-text, group A of docs/plans/ledger-close-plan.md). Every sentence named here was grepped in the public text before the ledger row moved. Rows name the earlier row they touch; nothing above is rewritten.

Row touched Ledger What changed (5 October 2026, night) Who next When
17, 48, 53, 56, 15 M2, M4, M7, M9, M10 Verified and moved to "Conceded, stated" (M10: "Answered with evidence, stated"). M10's overclaim 14 was still live at 18:20 UTC and is applied now: "bound by random memory access", 95 GB/s of useful loads against 1,638 GB/s sequential, RTX 5090 none done
19 M13 "a fifth" confirmed in For miners, Hardware (26.7 against 123 MH/s, 4 October 2026); moved none done
10, 11 F5, F10 Verified and moved none done
57, 21, 22, 24, 25, 26 P1, P3, P4, P6, P7, P10 Verified and moved. P3: overclaim 25 applied ("Wrapped for light clients ... phase two measurement") with the certificate-half numbers of bench-log round 6 (139 to 155 ms cold, 58 to 68 ms warm, laptop core, no phone); the wrapper stays Open for phase two measurement (the wrapper) before public repo
8, 27 E5, E6 E5 verified and moved. E6: one sentence in Security after the subsidy, "The schedule is a bet, not a measurement", Kaspa's reduction marked approximate; moved none done
28, 29, 9, 30, 32 G1, G2, G3, G4, G6 Verified and moved. G3: the entry's first Status line is now the Decided line (no team page; "The team is pseudonymous and there is no team page" in the litepaper), the older line kept prefixed "Was:" none done
14, 12, 13, 34, 49 C2, C3, C5, C6, C8, C10, C11 Verified and moved none done
(C13, M18, L8) C13, M18, L8 C13: "they say nothing about the price of a chip with the 256 MB cache on its die" in What Igneum does not claim. M18 verified. L8: "whether it is issued is Circle's decision" in Questions builders ask; Canto and Blast absent. All moved none done
6 L2 (text half) "so the people who show up early get the most" removed from Supply; schedule fact only. Counsel half unchanged, decision owner the founder the founder, counsel before public repo
110 L9 "Devnet: coins have no value and the chain may be reset." beside every download control on index, miner and wallet; the homepage tiles read "of emission to miners and provers; the protocol carries no fee" and "0% anyone else in the protocol". Not done: the same line on /live (outside this round's files) Claude (live page) now
111 M29 The litepaper's app paragraph rewritten to Ember 0.3.9 from the shipped UI; earnings, currency, game pause and the hardware wallet moved to a roadmap sentence; nothing from an unmerged branch none done
109 E16 (text half) The 20% row and the homepage bar now say the coinbase's 20% output is burned under igneum-proving-pool-v0 and provers are paid from the execution-state escrow credited with the same 20%; the single coinbase payout stays Open (code half, group D) consensus engineer (payout) before testnet
115 E17 (text half) "a million 100,000-gas calls a day" with the base unit marked Open; the fleet-size dependence sentence (4.9x today, 930x at 10,000 cards, approximate). Draw lines still owed measurement (draw lines) when convenient
94 E13 The six-row route table in the litepaper Economics ("Every payment route") and in the customer brief; source docs/design/payment-routes.md; moved to "Conceded, stated". That file's section 4 states are of 3 October and now lag the litepaper Claude (refresh payment-routes.md section 4) when convenient
1, 2, 39, 3, 4 X1, X2, X3, X7, X8 Verified and moved. X3: "Live rows arrive with the public testnet, August 2027" under the proofs feed (overclaim 61); the old sentence was already gone. X7 closes on the ledger's submission line (hello@igneum.network, spec issues) none done
36, 5 X9, X10, D2 Verified and moved; D2's sentence now reads "100,000-gas calls" (E17) none done

4. What the 3 October decisions close or change

Closed:

  • E4 (5% of gas is a tax): closed by (a). There is no fund and no 5%.
  • G8, the 60% half: narrowed by (a). The 60% spend vote no longer exists; CLAUDE.md keeps 60% signalling only for parameters genesis leaves to miners. The 90% upgrade signal and the pool-concentration risk remain.
  • O-5.4, the fund-contract half: closed by (a). Genesis contract and bridge key policies remain (row 74).
  • L3, the nameserver half: closed by (d) once the deSEC cut-over completes. The registrar half closes in December 2026. The host, the mirror and the seed-node rule remain (row 44).
  • X7, the ledger submission route: moot by (b). A contact route for the litepaper is still needed (row 3).
  • Overclaim 30's cross-reference to the ledger: dropped by (b). Overclaim 53 and the fund half of 46: superseded by (a), rewrite instead of applying.

Closed on the evening of 3 October 2026 (written into docs/spec/ the same evening):

  • F2: the quorum floor of rule v2 is the answer to the eclipse case (spec 3.3.2). O-3.7 is confirmation only.
  • F3: participation from every vote seen in blocks, votes are block payload (spec 3.3 Q2, 3.4.1). O-3.3 keeps the parameter.
  • P5: EVM semantics on the DAG (spec 7.1). O-2.8 removed.
  • P8 and C9: shard sortition, 8 provers, 10 s, then open, no shard bond (spec 7.2). O-5.1 keeps the measurement; O-5.6 is the job bond only.
  • E7: no bridged stablecoins at genesis, no official bridge, proof bridge in phase two (spec 7.3). Overclaims 38, 40 and 71 applied; O-5.2 keeps the settlement switch.
  • G7 and X6: client security policy (spec 08). The permanent line is on HP and LP. O-8.1 is the key custody policy.
  • The ledger's Count by status table and the eight Status lines were updated by the same commit.

Changed, not closed:

  • E3 (wash gas): under 80/20 a developer alone gets 20% of its own tip back and loses 80%. A developer who also mines the block gets 80% plus 20%, less the provers' part of the 80%. The only certain loss is the base fee. The ledger's "guaranteed loss of 20% of the tip plus the base fee" no longer holds. The founder confirms the 15% priority-fee burn is gone on purpose; if not, the split is 80/20 of what remains after a burn and the numbers in row 7 change.
  • E5 (dev fee to the founder's company): the ledger says the company carries development "until usage funds the development fund". There is no fund, so the company carries it for as long as the 1% fee, the pool and the proving business pay. That is the sentence the litepaper must carry, and it sharpens L1.
  • G5 (second client): "funded from the development fund as its first priority" has no funder. Row 47.
  • G3 (who are you): the anonymous founder is now the design, not a flaw to rebut. The ledger's "The founder's name is on every commit" is void. Row 9. The team-page-at-testnet decision needs re-confirming.
  • L1 and L2 (counsel): "offshore, parked" and "jurisdiction not yet named" become "offshore, being established", which is a jurisdiction counsel can be briefed in. Not closed until the opinion exists.
  • The ledger header ("Published alongside the litepaper") and its submission paragraph are now wrong under (b). Both lines were rewritten on 5 October 2026 under the later decision: published with the repository at the public testnet, submissions to hello@igneum.network or the repository issues.
  • Decision (e) makes CLAUDE.md stale: it still says the Vercel project lives in the other business's team (moved per commit 61aa946) and lists two organisation owners. Section 5 step 2.

Text the decisions force, beyond the overclaims list: row 7 lists every file. The design document is the eleventh place and the only one outside the repository.

5. Before the repository goes public, in order

The repository goes public at the public testnet (decision of 5 October 2026). The ledger and this file are published with it.

Nothing below is optional. The history, not just the working tree, carries the names: CLAUDE.md with the full name is in every commit, the ledger's earlier L2 text ("The founder is in the UK") is in the commits before 14ef6b3, and site/ledger.html (636 lines, the full ledger rendered) is in the commits before the same one. The commit author and committer on every commit is igneum-labs, and every commit carries a local-time offset one hour ahead of UTC, which is UK or Irish summer time in early October. A file edit fixes none of that.

  1. Keep the ledger in the tree and publish it with the repository (decision of 5 October 2026, which replaces decision b). docs/fud-ledger.md and this file (docs/fud-fixes.md) are on the public export list of tools/ci/identity-check.sh; every hit the check finds in them is reworded before the first public push, and no entry is removed. The ledger still maps the providers (GoDaddy, Vercel) and names .claude/agents/; the private export rules cover the founder's name, and the rest is reworded in place. The spec and the open-items file cite ledger ids (M7, F1, P8 and so on); those ids do not change.
  2. Rewrite CLAUDE.md as a public file. Remove: line 4 ("the founder's project"); every "the founder" (lines 22, 34, 39, 41, 46, 48, 52; "the founder's copy law" becomes "the copy law"); line 42 (the second owner the second owner login, "the founder, the igneum.network Google login", the sentence about 40 commits carrying his name); line 43 (other business's team; it is the igneum team now); line 44 (Neon id and London region); lines 46 to 49 (registrar, "Full Protection", the purchase quotes; after December the registrar changes anyway); lines 51 to 53 (the browser-profile section names every other business: the other business, QUANTUM, the earlier entity, the earlier business, another brand, another brand); the claude.ai artifact and doc links in "Source of truth" (they identify the tooling account). Move the operational notes (accounts, registrar, database id, browser profile, deploy scope) to a file outside the repository, for example ~/.config/igneum/NOTES.md.
  3. Scrub .claude/agents/cryptographer.md line 32 ("unless the founder overrides" becomes "unless the project lead overrides"). The other three agent files are clean. Decide whether .claude/agents/ stays public at all; if it does, it is the G2 disclosure and consistent with row 29.
  4. Rewrite the history once, before the first public push. Nothing is public and nobody has cloned, so the cheapest safe route is to squash to one root commit ("Igneum: public tree") authored by a neutral handle at a UTC timestamp. If the history is kept instead, run git filter-repo to: drop site/ledger.html from every commit; replace CLAUDE.md, the agent file, docs/fud-ledger.md and docs/fud-fixes.md in every commit with the scrubbed versions; rewrite every author and committer to the neutral handle; rewrite every date to +0000. Either way: rename the GitHub account igneum-labs to a handle without a name (the noreply address keeps its numeric id, so the rename is one setting), confirm the second owner login is no longer an organisation owner (decision e says one anonymous owner), and set TZ=UTC in whatever script commits from now on so no local-time offset appears again.
  5. Check the organisation and the account profiles: no location, no personal avatar, no personal email, 2FA on, the organisation's public members list empty. The Vercel team igneum and the Workspace are not visible from the repository; nothing to do there beyond step 2.
  6. Add a LICENSE and a root README. Neither exists (git ls-files shows no root README or LICENSE). A public repository without a licence invites the first issue to be about the licence. The founder picks the licence.
  7. Re-run the sweep from this evening on the final tree: git ls-files | xargs grep -nIE -f igneum-public/tools/identity.local (the private identity list, case-insensitive) must return nothing, and git log --format='%an %ae %cn %ce %ad' must show one neutral identity and +0000 only. Secrets: the history grep for connection strings and tokens returned zero hits today; repeat it after the rewrite.
  8. Fix the public text first (rows 1 to 41). The ledger's X1 answer is that the honest route is to open the repository with the bench logs, the simulator and the test report. Opening it with "no chip can ever" still on the homepage hands the first critic the ledger's own list.
  9. Put the GitHub links back on HP and the /bench page (row 1) on the day the repository opens, at the public testnet.

What is already clean: docs/bench-log.md and the /bench page name machines, not people (commit 1769eda); the live site returns 404 for everything under docs/ and 307 for /ledger; site/.env.local, site/.vercel/ and vendor/ are ignored; no tracked file carries a home-directory path; no connection string or token appears anywhere in the history. | 128 | P23 | The EVM pool has on_chain_block and no reorg hook, so a transaction unwound by a selected-chain reorg leaves the node until its sender resends (found by the P17 conformance run, 6 October 2026) | A reorg hook: unwound transactions handed back to the pool as pending with the usual checks; unit test; the conformance driver's reorged out case ends in executed without a resend (2 h) | execution engineer (round 3 ledger-rebase carries it) | before a public RPC | no |